paya

MindPaya · Legal

MindPaya Terms of Service

These terms govern the use of MindPaya, the organizational memory service provided by AnyPaya Oy. They are written for business customers. Plain language is intended; where a heading and a clause disagree, the clause applies.

Version
2026-09
Effective
11 September 2026
Provider
AnyPaya Oy, business ID 3640857-7, Helsinki, Finland
Contact
support@anypaya.ai
Related
MindPaya Privacy Notice

1. Who we are and what these terms cover

1.1 MindPaya is provided by AnyPaya Oy, a Finnish limited company with business ID 3640857-7 and registered office in Helsinki, Finland (“AnyPaya”, “we”, “us”).

1.2 MindPaya (the “Service”) is a memory service for organizations and the AI assistants they use. It stores what an organization and its assistants write to it, connects to sources the organization chooses, and gives the organization’s people and assistants back what is relevant, with its origin. The Service is available at app.mindpaya.ai and api.mindpaya.ai and through the MindPaya MCP server and connectors we publish.

1.3 These terms are an agreement between AnyPaya and the organization that creates or uses a MindPaya organization (the “Customer”, “you”). The person who creates an organization, accepts an invitation or otherwise uses the Service on the Customer’s behalf confirms that they are authorized to bind the Customer to these terms.

1.4 The Service is intended for companies, public bodies, associations and other organizations. It is not offered to consumers, and consumer protection law does not apply to it.

1.5 The MindPaya Privacy Notice describes how we handle personal data about the people who use the Service. Section 12 of these terms governs personal data contained in Customer Data. If AnyPaya and the Customer have signed a separate written agreement for the Service, that agreement prevails over these terms to the extent they conflict.

2. Your organization, sign-in and users

2.1 People sign in to the Service through AnyPaya ID, our sign-in service, using a Google account or another identity provider we support. Sign-in is subject to the identity provider’s own terms.

2.2 Each person who signs in must be at least 18 years old and act on behalf of the Customer. The Customer is responsible for everyone who uses its organization: the people it invites, the roles it gives them (owner, admin, member), the workspaces it opens to them and the sources it connects.

2.3 The Customer keeps sign-in credentials, API keys and connection codes confidential and uses them only for its own organization. The Customer tells us without undue delay at support@anypaya.ai if it suspects unauthorized use.

2.4 An organization must have at least one owner. Owners can rename the organization, manage members, billing and settings, and request deletion of the organization. Where these terms speak of a decision by the Customer, a decision by an owner is enough.

3. Registration codes and the free period

3.1 Creating an organization may require a registration code issued by AnyPaya. A registration code opens a free period and fixes its terms: how long it lasts, how many people can sign in to the organization during it and how many workspaces the organization can have. The Service shows these terms when the code is entered and afterwards in the organization’s settings.

3.2 During the free period the Service is provided without charge. The people who sign in first hold the organization’s places for the free period; when all places are taken, further people are refused until a place frees up or the organization moves to a paid plan. The same applies to workspaces.

3.3 When the free period ends, the Service stops accepting new content: new workspaces, sources, notes and memories are refused with a message stating the end date. Everything already stored stays readable, and the Customer’s assistants can still recall it. Nothing is deleted because a free period ended. Creating continues as soon as the organization is on a paid plan under Section 4.

3.4 A registration code is personal to the organizations AnyPaya gives it to. AnyPaya may revoke a registration code, or end a free period early, where the code is being misused, where the Service is used in breach of Section 6 or where the law requires it.

3.5 If an organization has not moved to a paid plan within twelve months after its free period ended and no one has signed in to it during that time, AnyPaya may delete the organization and its Customer Data after giving the owners at least 30 days’ notice by email.

4. Paid plans, fees and taxes

4.1 After the free period, continued creation in the Service requires a paid plan. Until self-service billing is available in the Service, plans are agreed in writing between the Customer and AnyPaya; email is sufficient. The plan, its price, the number of users and the billing period are as stated in that agreement or in AnyPaya’s current price list.

4.2 Prices are stated without value added tax and other applicable taxes, which are added as required by law. Invoices are payable within 14 days of the invoice date unless otherwise agreed. Late payments accrue interest under the Finnish Interest Act (korkolaki).

4.3 AnyPaya may change prices by notifying the Customer at least 30 days in advance; a change applies from the start of the Customer’s next billing period. The Customer may terminate the plan before the change takes effect.

4.4 If an invoice is more than 14 days overdue after a reminder, AnyPaya may put the organization in the same state as at the end of a free period under Section 3.3 until payment is made, and may terminate the agreement if the invoice remains unpaid 30 days after the reminder.

5. Customer Data

5.1 Customer Data means everything the Customer, its users, its AI assistants and its connected sources submit to the Service, and everything the Service derives from it for the Customer, such as memories, summaries, relations and maps.

5.2 Customer Data belongs to the Customer. The Customer grants AnyPaya a non-exclusive, royalty-free licence to host, copy, process, transmit and display Customer Data only as needed to provide, secure, support and improve the Service for the Customer and to comply with the law.

5.3 AnyPaya does not use Customer Data to train machine-learning models, does not sell it and does not make it available to other customers. AnyPaya personnel access Customer Data only to operate the Service, to give support the Customer has asked for or where the law requires it; such access is logged and visible to the Customer’s administrators in the Service.

5.4 The Customer is responsible for Customer Data: for having the rights and any lawful basis needed to submit it, including for content taken from connected sources and for personal data it contains, and for the instructions it and its assistants give the Service.

5.5 AnyPaya may use technical and usage information about how the Service is used (for example volumes, timings and error rates) in aggregated or de-identified form to operate and improve the Service.

6. Acceptable use

6.1 The Customer does not, and does not allow its users or assistants to:

6.2 If the Customer breaches this Section, AnyPaya may suspend or restrict the organization or individual users. AnyPaya gives notice before doing so where that is practicable and lifts the restriction when the breach is remedied.

7. AI assistants, connected sources and other third-party services

7.1 The Service is used through the Customer’s own AI assistants and tools, connected over the MCP protocol or the API, and through sources the Customer connects, such as Slack, GitHub or Google Drive. Those assistants, tools and sources are provided by third parties under their own terms. AnyPaya does not control them and is not responsible for them.

7.2 MindPaya itself does not send Customer Data to AI model providers. What the Customer’s assistants do with the content they recall from the Service is under the Customer’s control.

7.3 When the Customer connects a source, it authorizes the Service to read from that source within the permissions it grants. The Customer can disconnect a source at any time; Section 11 describes what happens to content already derived from it.

8. Availability, support and changes to the Service

8.1 AnyPaya aims to keep the Service available around the clock and announces planned maintenance in advance where possible. No service level is guaranteed unless agreed in writing.

8.2 Support is available by email at support@anypaya.ai on Finnish business days.

8.3 AnyPaya develops the Service continuously and may change or remove features. AnyPaya gives at least 30 days’ notice of changes that materially reduce the Service’s functionality, and at least 90 days’ notice if it discontinues the Service, during which the Customer can retrieve its Customer Data through the Service or its API.

9. Security and confidentiality

9.1 AnyPaya protects the Service and Customer Data with technical and organizational measures appropriate to the risk: the Service is hosted with providers in the European Union, data is encrypted in transit, access is limited to personnel who need it, administrative access is logged and backups are taken and deleted on a fixed schedule. The current measures are described in the Privacy Notice.

9.2 Each party keeps the other’s confidential information confidential and uses it only for the purposes of this agreement. Customer Data is the Customer’s confidential information. The obligation does not cover information that is public, already known to the receiving party or that the law requires to be disclosed, and it continues for three years after the agreement ends; for Customer Data it continues for as long as the data is held.

9.3 AnyPaya informs the Customer’s owners without undue delay after becoming aware of a security incident that affects the Customer’s Customer Data.

10. Intellectual property

10.1 The Service, its software, documentation, design and the AnyPaya and MindPaya names and marks belong to AnyPaya or its licensors. The Customer receives a limited, non-exclusive, non-transferable right to use the Service during the agreement in accordance with these terms.

10.2 If the Customer gives AnyPaya feedback or suggestions about the Service, AnyPaya may use them freely without obligation. Feedback never includes Customer Data.

11. Term, termination and deletion

11.1 These terms apply from the moment an organization is created and for as long as it exists.

11.2 The Customer may end the agreement at any time by having an owner request deletion of the organization in the Service’s settings or by email to support@anypaya.ai. Prepaid fees for an ongoing billing period are not refunded unless AnyPaya has terminated for its own convenience.

11.3 AnyPaya may terminate the agreement with 30 days’ notice if the Customer materially breaches these terms and does not remedy the breach within that time, with immediate effect where the breach is serious misuse under Section 6 or where the law requires it, and as provided in Sections 3.5 and 4.4.

11.4 When the agreement ends, access to the organization ends. AnyPaya deletes the organization’s Customer Data from the production systems within 30 days and from backups within a further 30 days. Records that AnyPaya must keep by law, such as accounting records, are kept for the period the law requires. Before deletion the Customer can retrieve its Customer Data through the Service or its API.

11.5 Content derived from a source the Customer disconnects stays in the organization until the Customer deletes it or asks AnyPaya to erase it; the Service offers erasure of a disconnected source and of the content derived from it.

12. Data processing terms

12.1 Where Customer Data contains personal data, the Customer is the controller and AnyPaya is the processor within the meaning of the EU General Data Protection Regulation (GDPR). This Section is the data processing agreement between the parties under Article 28 GDPR. For personal data about users that AnyPaya processes for its own purposes, such as sign-in and security, AnyPaya is the controller, as described in the Privacy Notice.

12.2 Subject matter and duration. AnyPaya processes personal data in Customer Data for the duration of the agreement in order to provide the Service. The nature of the processing is storage, indexing, deriving memories and summaries, retrieval and deletion. The data subjects are the Customer’s personnel and the people who appear in the content the Customer and its assistants submit; the categories of personal data are those the Customer chooses to submit.

12.3 Instructions. AnyPaya processes personal data only on the Customer’s documented instructions. Using the Service, its settings and its API constitutes the Customer’s instructions; further instructions are given in writing. AnyPaya informs the Customer if it considers an instruction to breach data protection law.

12.4 Confidentiality and security. AnyPaya ensures that the people it authorizes to process personal data are bound by confidentiality, and it implements the measures described in Section 9 and the Privacy Notice as its measures under Article 32 GDPR.

12.5 Sub-processors. The Customer gives AnyPaya general authorization to use the sub-processors listed in the Privacy Notice. AnyPaya informs the Customer of an intended addition or replacement at least 30 days in advance by updating that list and notifying the Customer’s owners by email; the Customer may object on reasonable data protection grounds and, if no solution is found, terminate the agreement before the change takes effect. AnyPaya imposes on its sub-processors data protection obligations equivalent to this Section and remains responsible for their performance.

12.6 Assistance. Taking into account the nature of the processing, AnyPaya assists the Customer with appropriate technical and organizational measures in responding to data subject requests, and with the Customer’s obligations under Articles 32 to 36 GDPR, including data protection impact assessments. AnyPaya notifies the Customer without undue delay after becoming aware of a personal data breach affecting Customer Data.

12.7 Transfers. AnyPaya processes Customer Data in the European Union and does not transfer it outside the European Economic Area without the Customer’s instruction or without safeguards that satisfy Chapter V GDPR.

12.8 Deletion and return. At the end of the agreement AnyPaya deletes personal data in Customer Data as described in Section 11.4, unless European Union or Finnish law requires it to be kept. The Customer can retrieve its data through the Service or its API before deletion.

12.9 Information and audits. AnyPaya makes available the information necessary to demonstrate compliance with this Section. The Customer may audit that compliance, itself or through an independent auditor bound by confidentiality, once in any twelve-month period and with at least 30 days’ notice, at its own cost and during business hours, and additionally where a supervisory authority requires it. AnyPaya may answer an audit request first by providing existing reports or certifications.

13. Warranties and disclaimers

13.1 AnyPaya provides the Service with reasonable skill and care. During a free period, and except as expressly stated in these terms, the Service is provided as is, without warranties of any kind, including of merchantability or fitness for a particular purpose.

13.2 Memories, summaries and other content the Service derives from Customer Data are produced automatically and may be incomplete or inaccurate. The Service shows the origin of what it returns so that it can be checked; the Customer verifies derived content before relying on it.

14. Liability

14.1 Neither party is liable to the other for indirect or consequential damage, such as loss of profit, revenue, business or goodwill, or for loss of data that the Customer could have retrieved through the Service before deletion.

14.2 AnyPaya’s total liability under this agreement for all claims in any twelve-month period is limited to the fees the Customer paid for the Service during the twelve months preceding the event giving rise to the claim. During a free period, when no fees have been paid, AnyPaya’s total liability is limited to EUR 1,000.

14.3 The limitations in this Section do not apply to damage caused wilfully or by gross negligence, or to liability that cannot be limited under mandatory law.

14.4 The Customer indemnifies AnyPaya against third-party claims arising from Customer Data or from the Customer’s use of the Service in breach of these terms, to the extent the claim is not caused by AnyPaya’s own breach.

15. Changes to these terms

15.1 AnyPaya may update these terms. Each version has a version number and an effective date, shown at the top of this page. The version the Customer accepted when creating its organization is recorded in the Service.

15.2 AnyPaya notifies the Customer’s owners of material changes at least 30 days before they take effect, by email or in the Service. If the Customer does not accept a change, it may end the agreement under Section 11.2 before the change takes effect. Continued use after the effective date constitutes acceptance. Changes required by law or that only add functionality may take effect immediately.

16. Governing law, disputes and general terms

16.1 This agreement is governed by the laws of Finland, excluding its conflict-of-law rules and the United Nations Convention on Contracts for the International Sale of Goods.

16.2 The parties first try to settle a dispute by negotiation. A dispute that is not settled within 60 days of one party’s written notice is resolved by the District Court of Helsinki (Helsingin käräjäoikeus) as the court of first instance.

16.3 Neither party may assign this agreement without the other’s consent, except that AnyPaya may assign it to a company in the same group or to a successor to its business on notice to the Customer.

16.4 Neither party is liable for delay or failure caused by events beyond its reasonable control, such as failures of public networks or power, acts of authorities or industrial action, for as long as the event lasts.

16.5 Notices to AnyPaya are sent to support@anypaya.ai. Notices to the Customer are sent to the email addresses of the organization’s owners, or shown in the Service.

16.6 These terms, the Privacy Notice and any written plan agreement form the entire agreement between the parties on the Service. If a provision is held invalid, the rest remains in force and the provision is applied to the extent permitted. The English text of these terms is binding; translations are provided for convenience.

Questions about these terms: support@anypaya.ai. AnyPaya Oy, business ID 3640857-7, Helsinki, Finland.